SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Audit & Controls, Security GRC

Anthropic - San Francisco, CA, United States - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 270,000 - 345,000 / annual

Anthropic's Security Governance, Risk, and Compliance (GRC) team is seeking a Security Audit & Controls Specialist to own and evolve the Common Control Framework (CCF) across all control domains. This individual contributor role is central to translating regulatory, customer, and voluntary obligations into controls that teams execute and that leadership can monitor continuously. You will own the CCF across every control domain—from access and change management to logging, encryption, and people controls. Key responsibilities include: • Own the canonical control set and its mappings to SOC 2, ISO 27001/42001, HIPAA, FedRAMP, and customer commitments, including the change process for adding, retiring, or rewording controls. • Draft and validate control descriptions and activities with control owners, ensuring each control clearly states who does what, how often, in which system, and what evidence proves it. • Design and run continuous monitoring of control efficacy: define metrics and automated tests that show operating effectiveness, tune out false positives, surface failures to owners before auditors do, and build a controls maturity model. • Verify remediation and carry fixes into steady state, advising on control design and implementation, confirming fixes against auditor requirements, and maintaining one source of truth for control and finding status. • Map new frameworks and commitments onto the CCF as they are adopted, and support gap assessments for new frameworks, certifications, products, or entities. • Support integrated audits and customer audits through readiness checks, walkthrough preparation, evidence request lists, and readout of external findings. • Evaluate evidence reliability, including the completeness and accuracy of system-generated and AI-generated evidence, and set the standard for audit-ready evidence. • Build with Claude: automate control mapping, evidence testing, and monitoring, and verify machine-drafted control language before it becomes the record. This role works well for someone who operates independently, writes clearly, and finds satisfaction in building a control set that is accurate, tested, and trusted by auditors and engineers alike. Building with Claude (Anthropic's AI) is a normal part of the job, with you deciding where human judgment stays in the loop. REQUIREMENTS: Minimum qualifications: • Several years in IT audit, security compliance, or controls assurance, including hands-on ownership of a control framework or control library across more than one framework (e.g., SOC 2, ISO 27001, FedRAMP, HIPAA). • Working command of audit mechanics: scoping, walkthroughs, sampling, design versus operating effectiveness, deficiency evaluation, and evidence reliability. • Experience writing control descriptions, control activities, and test procedures that other teams and external auditors relied on. • Experience with continuous controls monitoring or automated evidence collection, whether built, run, or audited. • Enough technical fluency to read a runbook, configuration, or pipeline definition and judge whether it enforces what the written control claims. • Clear writing, as control language and status reports are what auditors, engineers, and leadership work from. • Ability to get control owners and partner teams to prioritize and close work without having authority over them. Preferred qualifications: • Have designed or rebuilt a common controls framework and led remapping of existing frameworks onto it. • Have stood up continuous controls monitoring or automated evidence programs and can speak to coverage, false-positive rates, and impact. • Have applied LLMs to assurance work such as control drafting, framework mapping, evidence testing, or monitoring. • Have defined or assessed controls for AI systems or agents operating in production, or for home-built internal systems. • Have provided requirements for a homegrown GRC platform and worked with the engineers who build it. Education: Bachelor's degree in a related field or equivalent experience. Note: Certifications such as CISA or CISSP are welcome but not required. Prior AI-industry experience is not required.

Similar roles